Microsoft Investigates 'Moderately Critical' Windows XP Bug
Microsoft is currently investigating the emergence of a new critical bug affecting users of Windows 2000 and Windows XP. The Redmond-based firm made the announcement via Twitter on Tuesday, and says the issue can be found in the dynamic link library (.DLL) file "mfc42.dll."
Security firm Secunia posted a detailed report, which they say is based on a third party proof-of-concept exploit. It's suggested that the vulnerability can be exploited via PowerZip version 7.2 Build 4010, among other utilities that use the mfc42.dll file. (Source: pcmag.com)
Bug Affects Moderately Popular Component
The mfc42.dll file is a component in Microsoft Foundation Classes and a C++ application framework. It's not as popular as it once was, but remains useful enough to cause serious problems. Microsoft has for some time encouraged developers to seek alternatives to mfc42.dll.
The bug, which is related to a boundary error, can eventually result in a stack-based buffer overflow, says Secunia. What average users of Windows XP and Windows 2000 need to know is that this overflow can compromise the security of their machines.
Secunia: Issue "Moderately Critical"
Secunia says the vulnerability could allow malicious code to be executed if exploited properly, and in considering this the security firm has deemed the issue "moderately critical." (Source: cnet.com)
Although Windows XP and 2000 are confirmed affected by the bug, Secunia hasn't ruled out the possibility that other Microsoft operating systems could be vulnerable, too. However, it's more than likely that security updates added to Windows Vista and Windows 7 would block an attempt to exploit the flaw.
"Microsoft is investigating new public claims of a possible vulnerability in Windows 2000 and Windows XP," said company group manager Jerry Bryant, who said he's unaware of any attempts to exploit the code in order to launch an attack.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.